ClickFix campaign abuses Deno runtime for infostealer delivery

Summary

The ClickFix campaign has been observed to leverage the Deno runtime environment to deliver an infostealer. Attackers are utilizing compromised WordPress websites as lures, directing unsuspecting users to download and install the Deno runtime, which then facilitates the deployment of the malicious Python-based infostealer.

IFF Assessment

FOE

This campaign represents a new technique for delivering malware, making it harder for defenders to detect and block.

Defender Context

Defenders should be aware of novel malware delivery techniques like the use of the Deno runtime, as attackers continuously evolve their methods. Monitoring for unusual Deno installations or network traffic associated with it could be a valuable detection strategy.

Read Full Story →